CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)
CISA Warns of Trio of Actively Exploited SharePoint Server (TL-2026-1378), also tracked as SharePoint Trio Advisory, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-15 and last reviewed 2026-08-09. It is attributed to Storm-2603 (China) with medium confidence, affects Microsoft SharePoint Server Subscription Edition, references 6 CVEs (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), maps to 46 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 50 indicators of compromise.
Key facts for TL-2026-1378
- Threat ID
- TL-2026-1378
- Also known as
- SharePoint Trio Advisory, CISA July 2026 SharePoint Hardening Alert
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-08-09
- Attribution
- Storm-2603
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- government administration, finance, health, education, technology, manufacturing, critical infrastructure, energy
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 50
- Updates
- 2026-08-09 · 3 updates · revalidated 3× · latest source
Malware and tooling in CISA Warns of Trio of Actively Exploited SharePoint Server
Malware and tooling: WarLock, Storm-2603 activity cluster / CL-CRI-1040
CISA issued an advisory on July 14, 2026 warning that three on-premises Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are under active exploitation, with attackers gaining remote code execution and post-compromise persistence via theft of IIS/ASP.NET machine keys and deserialization abuse. Two additional July 2026 Patch Tuesday flaws (CVE-2026-55040, CVE-2026-58644) are rated 'Exploitation More Likely' but not yet confirmed exploited.
How CISA Warns of Trio of Actively Exploited SharePoint Server works
On July 14, 2026, CISA published an advisory urging administrators to harden on-premises Microsoft SharePoint Server deployments after confirming active, in-the-wild exploitation of three vulnerabilities: CVE-2026-32201 (CVSS 6.5, spoofing via improper input validation enabling unauthenticated reflected XSS/impersonation, disclosed March 2026 and added to CISA's KEV catalog on 2026-04-14), CVE-2026-45659 (CVSS 8.8, remote code execution via deserialization of untrusted data, requiring only Site Member-level authentication, patched May 2026 and added to KEV on 2026-07-01 despite Microsoft's initial 'exploitation less likely' rating), and CVE-2026-56164 (CVSS 5.3, elevation of privilege via missing authentication for a critical function, shipped in July 2026 Patch Tuesday and added to KEV the same day it was disclosed, 2026-07-14).
All three affect every supported on-premises SharePoint Server edition (Subscription Edition, 2019, and 2016/Enterprise Server 2016); SharePoint Online/Microsoft 365 is not affected. Post-exploitation activity observed by CISA and Microsoft involves theft of IIS/ASP.NET machine keys and abuse of .NET deserialization to forge authentication tokens, maintain persistence across patch cycles, and deploy malware. This tradecraft mirrors the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704/49706/53770/53771), in which the China-based actor Storm-2603 (aka Warlock Group / GOLD SALEM), along with Linen Typhoon and Violet Typhoon, exploited on-prem SharePoint to drop the spinstall0.aspx web shell, exfiltrate ASP.NET machine keys via a crafted GET request, establish persistence through scheduled tasks and Group Policy Object modification, and ultimately deploy Warlock ransomware via DLL search-order hijacking. Storm-2603 has continued targeting on-prem SharePoint with the same machine-key-theft objective roughly a year later, reusing the tactic against the newly disclosed 2026 CVEs.
Two further July 2026 Patch Tuesday SharePoint flaws are not yet confirmed exploited but carry Microsoft's 'Exploitation More Likely' designation and CISA flagged them as high-priority: CVE-2026-55040 (CVSS 9.1, critical security-feature bypass; the first half of a two-bug chain whose second, still-embargoed component is expected to complete an unauthenticated RCE chain in August 2026) and CVE-2026-58644 (CVSS 9.8, critical unauthenticated network RCE). Shadowserver telemetry cited in coverage counted roughly 10,000 internet-exposed on-prem SharePoint instances, with over 800 still unpatched against CVE-2026-32201 and CVE-2026-45659 as of the advisory date. CISA's Binding Operational Directive timeline required FCEB agencies to remediate CVE-2026-45659 by 2026-07-04 and the newly added CVE-2026-56164/CVE-2026-32201 exploitation by 2026-07-17. Recommended mitigations include immediate patching, enabling AMSI integration for SharePoint (to catch malicious POST requests), deploying Microsoft Defender AV, placing a Layer 7 reverse proxy in front of SharePoint, restricting external access to SharePoint Central Administration, rotating ASP.NET machine keys after patching, and enhanced logging for anomalous IIS/w3wp.exe activity.
MITRE ATT&CK techniques used in TL-2026-1378
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process; T1606 Forge Web Credentials
Collection
T1005 Data from Local System; T1074 Data Staged; T1560 Archive Collected Data
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Defense Evasion
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1078 Valid Accounts; T1098 Account Manipulation; T1505 Server Software Component
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1134 Access Token Manipulation; T1484 Domain or Tenant Policy Modification
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
stealth
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning; T1596 Search Open Technical Databases
Affected products and versions in CISA Warns of Trio of Actively Exploited SharePoint Server
- Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: all builds prior to July 2026 cumulative update
Fixed in: July 2026 Patch Tuesday cumulative update - Microsoft — SharePoint Server 2019
Vulnerable versions: all builds prior to July 2026 security update
Fixed in: July 2026 security update (KB per Microsoft Update Catalog) - Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: all builds prior to July 2026 security update
Fixed in: July 2026 security update (KB per Microsoft Update Catalog)
Remediation for CISA Warns of Trio of Actively Exploited SharePoint Server
Patches
- Microsoft April 2026 Patch Tuesday update — CVE-2026-32201
- Microsoft May 2026 Patch Tuesday update — CVE-2026-45659
- Microsoft July 2026 Patch Tuesday update — CVE-2026-56164, CVE-2026-55040, CVE-2026-58644
Immediate actions
- Apply Microsoft's May 2026 and July 2026 SharePoint security updates covering CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644 without delay
- Rotate ASP.NET/IIS machine keys on all on-premises SharePoint Server instances after patching, since theft of the pre-existing keys survives a patch alone
- Restrict or remove external/internet exposure of SharePoint Central Administration
- Hunt for spinstall0.aspx and similarly-named .aspx artifacts (spinstall1.aspx, spinstall2.aspx) dropped into LAYOUTS directories
Workarounds
- Where immediate patching is not possible, isolate on-prem SharePoint Server from the internet and restrict access to a trusted VPN/reverse-proxy path
- Monitor for and block outbound connections to ngrok and similar tunneling services from SharePoint application servers
Longer-term hardening
- Enable Windows Antimalware Scan Interface (AMSI) integration for SharePoint to scan and block malicious POST request bodies
- Deploy Microsoft Defender Antivirus (or equivalent EDR) with up-to-date detections on all SharePoint front-end and application servers
- Place a Layer 7 reverse proxy / WAF in front of internet-facing SharePoint deployments
- Establish enhanced logging and alerting on anomalous w3wp.exe child-process activity, scheduled task creation, and Group Policy Object changes
CVEs associated with CISA Warns of Trio of Actively Exploited SharePoint Server
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, CVE-2026-58644, CVE-2026-50522
Weaknesses (CWE) in CISA Warns of Trio of Actively Exploited SharePoint Server
CWE-290, CWE-79, CWE-502, CWE-306, CWE-288, CWE-20, CWE-1390
Timeline of CISA Warns of Trio of Actively Exploited SharePoint Server
Showing the 20 most recent tracked events.
- CISA adds CVE-2026-45659 to the KEV catalog after confirming active in-the-wild exploitation despite the patch having shipped in May.
- CISA Binding Operational Directive remediation deadline for FCEB agencies to patch CVE-2026-45659.
- Microsoft July 2026 Patch Tuesday releases security updates for multiple SharePoint Server vulnerabilities including CVE-2026-50522 and CVE-2026-56164; CISA issues SharePoint hardening alert urging AMSI Full Mode and machine key rotation.
- CISA publishes the advisory 'CISA Urges SharePoint Hardening After New Exploitations,' warning of active exploitation of the three CVEs and highlighting IIS machine-key theft and deserialization post-exploitation tradecraft.
- CISA adds CVE-2026-56164 to the KEV catalog the same day it is disclosed, citing active exploitation via missing authentication for a critical function.
- Microsoft's July 2026 Patch Tuesday (622 CVEs total) discloses CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644 affecting on-prem SharePoint Server.
- Microsoft updates its advisory for CVE-2026-58644 (deserialization RCE, CVSS 9.8) to confirm active exploitation detected in the wild, days after July 2026 Patch Tuesday disclosure.
- The Register, BleepingComputer, and other outlets report on the CISA advisory, noting Shadowserver telemetry of ~10,000 internet-exposed SharePoint instances with 800+ unpatched hosts.
- CISA adds CVE-2026-58644 (SharePoint unauthenticated deserialization RCE, CVSS 9.8) to the KEV catalog, confirming active exploitation of a flaw the advisory had only rated 'Exploitation More Likely.'
- Tenable publishes a consolidated FAQ on the chained SharePoint exploitation, summarizing CVSS/VPR scoring, AMSI/Defender IOCs (AK47 C2, NSecKrnl.sys BYOVD, LockBit Black), and mitigation guidance.
- Defused security researchers detect an undocumented SharePoint deserialization vector in active attacks, initially unable to tie it to a specific CVE.
- CISA Binding Operational Directive remediation deadline for FCEB agencies to address CVE-2026-32201 and CVE-2026-56164 exploitation.
- Security researcher Janggggg publishes a public PowerShell PoC exploit for CVE-2026-50522 on GitHub; watchTowr confirms structural legitimacy and captures active exploitation attempts within hours via its Attacker Eye honeypot network.
- CISA adds CVE-2026-50522 to the KEV catalog with a remediation deadline of July 25, 2026; Microsoft publishes a security blog detailing Storm-2603 activity delivering Warlock ransomware via exploited SharePoint servers.
- CERT-EU issues Security Advisory 2026-009 warning EU institutions of active exploitation and recommending immediate patching, credential rotation, and compromise assessments.
- FOITT (Switzerland's Federal Office for Information Technology, Systems and Telecommunication) security specialists detect anomalous access patterns on its on-premises SharePoint servers.
- FOITT confirms approximately 200 user and technical accounts compromised; initiates incident response including password resets and full server reinstallation.
- FOITT publicly discloses the cyberattack, attributing it to 'previously unknown actors' presumably exploiting the SharePoint vulnerability chain; investigation supported by Switzerland's BACS and Microsoft.
- BleepingComputer is first to publicly report the Swiss government SharePoint breach, naming the agency as BIT (Federal Office of Information Technology, Systems and Telecommunication) and tying the suspected root cause specifically to CVE-2026-56164 and/or CVE-2026-50522.
- Help Net Security and Cyber Security News publish additional coverage; BIT confirms affected servers are being reinstalled and external access remains blocked pending completion, with no threat actor having claimed responsibility and no evidence of data exfiltration beyond the ~200 compromised account credentials.
Update history for TL-2026-1378
- 2026-08-09 — Swiss Federal IT Office (BIT) SharePoint Breach — 200 Accounts Compromised via Suspected CVE-2026-56164/CVE-2026-50522 Exploitation: What changed No severity/exploitability/status escalation — the existing CRITICAL/ACTIVE assessment already covers this. The update sharpens which CVEs are suspected in the Swiss BIT/FOITT breach (CVE-2026-56164 and/or CVE-2026-50522, both
- 2026-08-04 — Active Exploitation of CVE-2026-50522 SharePoint Deserialization RCE in Compromise of Switzerland's FOITT (Federal IT Agency): What changed A sixth vulnerability, CVE-2026-50522 (CVSS 9.8 unauthenticated deserialization RCE via the WS-Federation /_trust/default.aspx endpoint), joins the exploitation chain, and CVE-2026-58644 — previously only 'Exploitation More Lik
- 2026-07-16 — Active Exploitation of Chained SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, CVE-2026-58644): What changed CVSS escalated 8.8 → 9.8, reflecting confirmed in-the-wild exploitation of CVE-2026-58644 (CVSS 9.8) on 2026-07-15, one week after the original advisory. Severity/exploitability/status were already CRITICAL/ACTIVE/ACTIVE and re
Sources cited for CISA Warns of Trio of Actively Exploited SharePoint Server
- CISA Urges SharePoint Hardening After New Exploitations
- CISA sounds alarm over trio of exploited SharePoint flaws
- CISA warns admins to patch actively exploited SharePoint flaws
- CVE-2026-32201: SharePoint Server Auth Bypass Vulnerability
- GitHub PoC: CVE-2026-32201-exploit (reflected XSS via spoofing flaw)
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- CVE-2026-45659: Microsoft SharePoint Server Deserialization Remote Code Execution (CISA KEV)
- CVE-2026-45659, SharePoint on KEV and Warlock ransomware (campaign continuity analysis)
- Security Update Guide - CVE-2026-45659
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
- Microsoft Patch Tuesday - July 2026 (SharePoint CVE-2026-55040, CVE-2026-58644, CVE-2026-56164)
- The July 2026 Security Update Review
- Disrupting active exploitation of on-premises SharePoint vulnerabilities (ToolShell precursor campaign)
- Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems
Threats related to CISA Warns of Trio of Actively Exploited SharePoint Server
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)
- CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog
Detection coverage for TL-2026-1378
As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1378 across Splunk SPL, Microsoft KQL and Sigma, covering 50 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.